(This text was translated from English into German with the help of AI.)
What is more worthy of discussion is the fact that the work of the US company is described as ‘without alternative’. This is precisely where a fundamental problem lies: digital sovereignty does not mean doing without international technology, solutions and providers. Instead, it is about having the freedom to choose. Particularly within the German and European cyber security sector, there are companies with extensive expertise in incident response, IT forensics and the protection of critical IT infrastructure. Why was none of these firms called upon in Berlin to investigate the incident?
The case of the federal capital therefore provides an opportunity to fundamentally scrutinise procurement and decision-making processes:
- How do we ensure that, in the event of a far-reaching and successful cyber-attack, Germany is not dependent on specific non-European technologies?
- Are European suppliers given sufficient consideration in projects that are particularly critical to security?
- What role do the location of providers’ headquarters, the applicable legal framework and potential access to sensitive data play?
We have companies and specialists in Germany with extensive experience in incident response and IT forensics. They can investigate attacks, restore systems and then determine what needs to be changed to prevent something like this from happening again. We are constantly discussing digital sovereignty. At the same time, we are awarding a contract to a US company that provides very deep insight into government IT. And to do so, we are installing software with correspondingly far-reaching permissions. To me, that doesn’t add up.
Anyone wishing to strengthen digital sovereignty must ensure that alternatives emerge. However, that alone is not enough. These alternatives must have a chance of being considered when it really matters. That did not happen in Berlin.
Perhaps we should therefore spend less time debating whether American or European cyber security is fundamentally ‘better’. The more important question is: do we want to remain permanently in a situation where, in the event of a security-critical incident, only one provider appears to be the only option? Our goal should be different: a strong and extensive European security ecosystem that is not only technologically competitive. This would give public institutions in Germany a genuine choice, even when it comes to critical security decisions.
What does digital sovereignty mean?
It is crucial to be able to make independent decisions regarding the use of technologies, IT systems and data. For businesses and public institutions, this means, in particular, retaining control over their digital infrastructure and sensitive information, and reducing critical dependencies on individual providers or states.
For us at G DATA, digital sovereignty is therefore closely linked to cyber security and trust. As a German cyber defence company, G DATA develops its security solutions using its own expertise and adheres to high standards of data protection, transparency and security. However, digital sovereignty means more than just ‘Made in Germany’ or ‘Made in Europe’: what is crucial is that organisations retain choices, consciously assess risks and dependencies, and remain capable of acting at all times. Those who can protect and control their IT and data thereby also strengthen their own digital self-determination.
